首页    期刊浏览 2024年11月24日 星期日
登录注册

文章基本信息

  • 标题:Feature interaction: the security threat from within software systems
  • 作者:Armstrong NHLABATSI ; Robin LANEY ; Bashar NUSEIBEH
  • 期刊名称:Progress in Informatics
  • 印刷版ISSN:1349-8614
  • 电子版ISSN:1349-8606
  • 出版年度:2008
  • 期号:5
  • 页码:75-89
  • DOI:10.2201/NiiPi.2008.5.8
  • 出版社:National Institute of Informatics
  • 摘要:Security engineering is about protecting assets from harm. The feature interaction problem occurs when the composition of features leads to undesirable system behaviours. Usually, this problem manifests itself as conflicting actions of features on a shared context. Security requirements may be violated by feature interactions creating security vulnerabilities which can potentially be exploited by attackers. In thispaper, we discuss the feature interaction problem and some of its possible implications for security requirements. The paper concludes that (1) the detection of the violation of security requirements by feature interactions is not different from other types of requirements - what differs is the impact of such violation; and (2)feature interaction detection approaches can be used as a means for vulnerability analysis.
  • 关键词:Security requirements; feature interaction detection; vulnerability analysis
Loading...
联系我们|关于我们|网站声明
国家哲学社会科学文献中心版权所有